Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech • Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis
SECURITY

Analysis: Hackers exploit 29 zero-days on second day of Pwn2Own Automotive

Pwn2Own Automotive 2026: A New Wave of Zero-Day Exploits

Pwn2Own Automotive 2026: A New Wave of Zero-Day Exploits

In the rapidly evolving world of cybersecurity, the annual Pwn2Own Automotive contest serves as a significant benchmark for identifying and addressing vulnerabilities in the automotive sector. This year's event, held in Tokyo, Japan, from January 21 to 23, has once again highlighted the urgent need for robust security measures in the automotive industry.

Day 2 Highlights: A Hacking Frenzy

On the second day of the competition, security researchers demonstrated their skills by exploiting 29 unique zero-day vulnerabilities across various electric vehicle (EV) chargers, in-vehicle infotainment (IVI) systems, and car operating systems. The total cash awards for the day amounted to $439,250.

Leading the Pack: Fuzzware.ioc

Fuzzware.ioc emerged as the frontrunner, earning $213,000 by hacking the Phoenix Contact CHARX SEC-3150 charging controller, the ChargePoint Home Flex EV charger, and the Grizzl-E Smart 40A EV charging station.

Other Notable Achievements

Sina Kheirkhah of Summoning Team and Rob Blakely of Technical Debt Collectors, along with Hank Chen of InnoEdge Labs, also demonstrated impressive zero-day exploit chains, earning $40,000 each.

Implications for the North East Region and India

The growing number of zero-day exploits in the automotive sector is a global concern, and the North East region of India, with its burgeoning EV market, is not immune to these threats. As the adoption of EVs increases, so too does the need for robust security measures to protect against such vulnerabilities.

Looking Ahead: Day 3 and Beyond

On the third day of Pwn2Own, teams will continue their efforts to exploit more zero-day vulnerabilities. The Grizzl-E Smart 40A, Alpitronic HYC50, and Autel MaxiCharger are among the targets for the day. The complete schedule for the contest is available online.

A Continuing Trend

Pwn2Own Automotive 2026 marks the third consecutive year that hackers have collected substantial rewards for exploiting zero-day vulnerabilities. This trend underscores the need for vendors to prioritize security fixes and for the industry as a whole to remain vigilant against emerging threats.